CrowdSec
CrowdSec reads structured Caddy access logs through an acquisition source labeled as Caddy input. Its Hub collection supplies parsing and scenario logic; a separate firewall bouncer polls decisions and enforces them through firewalld.
Detection is not enforcement
Installing a parser or scenario does not prove that requests are read, parsed, turned into decisions, collected by the bouncer, or blocked at the firewall. Validation follows that complete chain: configuration, acquisition metrics, engine activity, alerts and decisions, bouncer registration and recent polling, then a controlled short ban from a different public address.
The address carrying the active administrative session is never used for a ban test. Detection and enforcement are diagnosed separately, so an empty acquisition stream is not mistaken for a firewall problem and a stale bouncer is not mistaken for failed parsing.